Skip to content

A–Z

Glossary

Plain-language definitions of the USB forensics terms used across the guides.

ContainerID
A GUID Windows gives to all device nodes that belong to the same physical device, linking Enum\USB, Enum\USBSTOR and SWD\WPDBUSENUM entries.
Device instance ID
The path-like name Windows gives a device node, such as USBSTOR\Disk&Ven_X&Prod_Y&Rev_1.00\SERIAL&0, used across the registry, logs and setupapi.
Device property timestamps (0064–0067)
FILETIMEs under a device's Properties\{83da6326-…} key: 0064 install date, 0065 first install, 0066 last arrival, 0067 last removal.
EMDMgmt
A SOFTWARE hive key written by ReadyBoost that pairs a USB device's serial with its volume label and volume serial number.
MountedDevices
The SYSTEM hive key mapping drive letters and volume GUIDs to the disk or device each volume belongs to.
MountPoints2
The NTUSER.DAT key listing volumes mounted in a user's session, by volume GUID: the registry link between a USB device and an account.
Partition/Diagnostic event 1006
The Windows 10+ event logged on each disk arrival, with model, serial, capacity, partition table and volume boot records.
USBSTOR
The SYSTEM hive key Enum\USBSTOR, where Windows keeps one entry per USB mass-storage device with vendor, product, revision and serial.
Volume GUID
The identifier Windows assigns to each volume it mounts, as in \\?\Volume{…}; it links MountedDevices to each user's MountPoints2.
Volume serial number (VSN)
The 32-bit serial written into a volume's boot sector when it is formatted, shown as XXXX-XXXX and stored in shortcuts and Jump Lists.
Windows-generated serial
A USB instance ID made up by Windows when the device reports no usable serial, recognisable by an & in second position, as in 7&1f2e3d4c&0.
WPDBUSENUM
The Windows Portable Devices enumerator: SWD\WPDBUSENUM registry entries whose FriendlyName is a USB volume's label or drive letter.